ICT Security Services Solution for Tourism Ireland
Value
€160k
Deadline
11 Oct
11 Oct 2024
Value
€160k
Deadline
11 Oct
Provision of ICT security services for Tourism Ireland over three years
Provision of ICT security services for Tourism Ireland over three years
Bidder profile
Small to medium-sized enterprises with experience in ICT security services and a proven track record in similar projects.
Risks & flags
- Turnover requirement may limit participation
- Ambiguity in insurance requirements
- Reliance on annual performance reviews for contract renewal
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
Buyer Title CPV / category Estimated value Per-year Procedure type Lots Location Contract length Submission deadline Go-live / start |---------------------|---------------------------------|----------------|----------------|----------|----------------|------|----------|------------------|-----------------------------|--------------------------| Tourism Ireland CLG ICT Security Services Solution Services €160,000 not stated Open Procedure not stated not stated 3 years (with possible 1-year extension) 11th October 2024, 12:00 1st January 2025
2. Scope of Work
The contract involves the provision of ICT Security Services to Tourism Ireland, which includes a comprehensive range of security assessments and advisory services. The contractor will perform day-to-day activities that ensure the security of Tourism Ireland’s ICT infrastructure, which includes a hybrid network with both on-premises and cloud-hosted services.
The key activities include:
- Vulnerability Assessments: Conduct both external and internal vulnerability assessments and penetration tests on Tourism Ireland’s servers and systems as required.
- Application Security Testing: Perform unauthenticated and authenticated application security testing on internal and external websites and applications.
- Automated and Manual Testing: Carry out automated and manual application security testing on various platforms.
- Reporting: Present findings from security testing in a clear and concise report format in a timely manner.
- Liaison: Work closely with Tourism Ireland’s ICT Security Officer regarding all security testing activities.
- Advisory Services: Provide advice to the ICT Security Officer and third-party suppliers concerning vulnerabilities discovered and recommendations for remediation.
- Proactive Threat Monitoring: Keep the ICT Security Officer informed of the latest security threats and vulnerabilities relevant to Tourism Ireland’s operations.
- Project Participation: Define and participate in ICT Security Projects as necessary.
- Meetings: Attend regular meetings, including formal Quarterly Business Reviews (QBRs).
The contract is structured to provide 20 days of ICT Security Services per annum, with additional days available as required. The contractor must also provide 2 days per annum for formal security briefings.
3. Background & buyer context
Tourism Ireland, established under the Belfast Agreement, is responsible for marketing the island of Ireland as a holiday destination. The procurement of ICT Security Services is driven by the need to enhance the security posture of its ICT infrastructure, which includes managing over 60 servers, 400+ PCs, and 200 mobile devices across multiple global offices. This initiative aligns with ongoing efforts to strengthen cybersecurity measures in response to evolving threats and vulnerabilities.
4. Eligibility & selection criteria
Bidders must meet the following eligibility and selection criteria:
- Turnover requirement: Minimum average annual turnover of €100,000 over the last three financial years.
- Insurance:
- Employer’s Liability Insurance with an indemnity limit of €13,000,000.
- Public Liability Insurance with an indemnity limit of €6,000,000.
- Professional Indemnity Insurance with an indemnity limit of €1,000,000.
- Certifications: Not specified for this tender.
- Past experience: Candidates must demonstrate experience with at least three comparable projects within the last three years.
- Personnel: Candidates must have personnel with relevant experience, although specific roles and years of experience are not detailed.
- Geographic / facility constraints: Not specified for this tender.
5. Award criteria & scoring
Bids will be evaluated based on the following criteria:
| Criterion | Weight (%) | Sub-criteria | Pass/Fail Thresholds |
|---|---|---|---|
| Ultimate Cost of Services | 50 | N/A | N/A |
| Technical Merit of proposed solution | 30 | N/A | 18% |
| Differentiators and Innovation | 10 | N/A | 6% |
| Account Management & Reporting Capabilities | 10 | N/A | 6% |
The evaluation will follow a Most Economically Advantageous Tender (MEAT) approach, with a minimum scoring threshold for certain qualitative criteria.
6. Submission requirements
Bidders must submit the following documentation:
- Method statement / response document: Must follow the template provided, with no specified page limit.
- CVs: For key personnel, with no specified page count.
- Pricing schedule: Must be formatted according to the provided template.
- Case studies: At least three case studies of similar projects, with values ranging from €100,000.
- Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest declarations.
- Mandatory site visit: Not specified for this tender.
- Submission portal: All submissions must be made via the electronic Tender Upload facility on www.etenders.gov.ie.
7. Key dates & process
| Event | Date |
|---|---|
| RFT issued | 16th September 2024 |
| Clarification deadline | 12:00 Noon, 26th September 2024 |
| Tender deadline | 12:00 hours, 11th October 2024 |
| Expected award | 9th December 2024 |
| Contract start | 1st January 2025 |
8. Contract terms that matter
Key contract terms include:
- Term and extension: The initial contract period is three years, with the possibility of a one-year extension based on performance.
- Payment terms: Not specified in the documents.
- Key SLAs/KPIs: Not specified in the documents.
- Liquidated damages: Not specified in the documents.
- Termination clauses: Not specified in the documents.
- IP ownership: Not specified in the documents.
- Sub-contracting rules: Not specified in the documents.
9. Risks, red flags & unusuals
Potential risks and concerns include:
- The turnover requirement of €100,000 may limit participation to smaller firms, potentially excluding capable bidders.
- The lack of specified insurance requirements for certain types may create ambiguity for bidders.
- The contract's reliance on annual performance reviews could introduce uncertainty regarding contract renewal.
10. SME fit assessment
This tender is suitable for small to medium-sized enterprises (SMEs) that have:
- Experience in providing ICT security services, particularly in vulnerability assessments and penetration testing.
- The capacity to meet the insurance requirements specified.
- A proven track record of similar projects, ideally with references from past clients.
- The ability to provide personnel with relevant experience in cybersecurity.
Consortium or subcontracting arrangements are not explicitly mentioned, but may be permissible. Preparation for the bid may require several days of effort, including gathering documentation and preparing case studies. The presence of established firms in the sector may indicate a competitive environment.
11. Where to dig deeper
- Source RFT filename: INSTRUCTIONS ICT Security Services 2025.pdf
- eTenders CFT ID: ICTRD2024/01
- Contact email: Not specified; queries must be submitted via the eTenders messaging option.
- Important attachments:
- Appendix 1 — Suitability Criteria
- Appendix 2 — Award Criteria
- Schedule 1 — Specification Document
This tender has been awarded
- Waystone Compliance Solutions (IE) Limited · 10 Oct 2025
- Waystone Compliance Solutions (IE) Limited · 10 Feb 2025
Can you bid?
Minimum turnover
€100,000
Public liability insurance
€6,000,000
Professional indemnity insurance
€1,000,000
Scoring
Most Economically Advantageous Tender
Documents (6)
INSTRUCTIONS ICT Security Services 2025.pdf
562.8 KB · RFT / Invitation to Tender
SecurityServices.xlsx
11.8 KB · Pricing / BOQ / Schedule of Rates
SCHEDULE 3.1 Services Contract (Tourism Ireland) 2023 EEA.pdf
310.6 KB · Contract / Agreement / Terms
SCHEDULE 3.2 Services Contract (Tourism Ireland) Non EEA 2023.pdf
595.5 KB · Contract / Agreement / Terms
CLARIFICATION in Response to Queries Received - ICT Security Services Solution.pdf
203.7 KB · Clarification / Addendum
SCHEDULE 2 RESPONSE Document - ICT Security Services Solution 2025.doc
281.0 KB
Original notice text
Tourism Ireland seeks ICT security services, including vulnerability assessments, application security testing, and proactive threat monitoring, to enhance its cybersecurity posture.
AI analysis updated 3 months, 4 weeks ago
Value
€160k
Deadline
11 Oct
Buyer
Tourism Ireland CLGLocation
Services provided to Tourism Ireland, which operates globally.
Procedure
Open
Clarification
26 Sep 2024
eTenders ID
4323634
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender